CVE-2024-25506: Processmaker

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

Affected products

Published 2024-03-28. Last modified 2026-06-17.